CVE-2004-0968: Low severity gnu glibc vulnerability
Published Oct 20, 2004
·Updated
The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.
Affected Software
34 affected componentsFixes available
ubuntu/glibc<2.3.6-0ubuntu20
2.3.6-0ubuntu20
ubuntu/glibc<2.3.6-0ubuntu20
2.3.6-0ubuntu20
ubuntu/glibc<2.3.6-0ubuntu20
2.3.6-0ubuntu20
debian/glibc
2.31-13+deb11u102.36-9+deb12u72.38-14
GNU glibc=2.0
GNU glibc=2.0.1
GNU glibc=2.0.2
GNU glibc=2.0.3
GNU glibc=2.0.4
GNU glibc=2.0.5
GNU glibc=2.0.6
GNU glibc=2.1
GNU glibc=2.1.1
GNU glibc=2.1.1.6
GNU glibc=2.1.2
GNU glibc=2.1.3
GNU glibc=2.1.3.10
GNU glibc=2.1.9
GNU glibc=2.2
GNU glibc=2.2.1
GNU glibc=2.2.2
GNU glibc=2.2.3
GNU glibc=2.2.4
GNU glibc=2.2.5
GNU glibc=2.3
GNU glibc=2.3.1
GNU glibc=2.3.2
GNU glibc=2.3.3
GNU glibc=2.3.4
GNU glibc=2.3.10
redhat Enterprise Linux=3.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux Desktop=3.0
Remediation
Patch Available
Event History
Oct 20, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Jun 13, 2024
Data Sourced
via Launchpad·04:22 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0968?
CVE-2004-0968 is considered to have a high severity due to the potential for local users to overwrite files.
2
How do I fix CVE-2004-0968?
To fix CVE-2004-0968, upgrade the glibc package to version 2.3.6-0ubuntu20 or later for Ubuntu systems.
3
What versions of glibc are affected by CVE-2004-0968?
CVE-2004-0968 affects glibc versions 2.3.2 and earlier.
4
Can CVE-2004-0968 be exploited remotely?
No, CVE-2004-0968 is a local vulnerability that requires local access to exploit.
5
Which operating systems are affected by CVE-2004-0968?
CVE-2004-0968 primarily affects versions of Ubuntu and Red Hat Enterprise Linux using vulnerable glibc versions.